For users
Privacy Notice
This is a draft. It has not been through legal review.
Until the final version replaces it, read this as a plain account of what we actually do today. Anything not yet settled is left blank and listed in §08 — we have not written unsettled matters as though they were settled.
What this notice covers
This notice explains where TROPS received personal information on trops.kr, what we use it for, and when we delete it.
We no longer receive any new personal information on trops.kr. Enquiries reach us by email at contact@theo-ne.com, and we delete those messages once we have answered them.
Documents from pre-check intakes made on trops.kr up to 20 August 2026 are still held. We no longer accept them, but what remains is kept and deleted exactly as §02 and §03 below set out.
Pre-check intake has moved to app.trops.kr. Processing that happens there is covered by that site's own privacy notice.
We run no advertising identifiers or behavioural tracking on this site. We set no analytics or advertising cookies, and we keep nothing in browser storage that identifies you or ties one visit to another.
One of two exceptions: a functional cookie, lang, remembers which language (Korean/English) you're reading in (2026-08-21). Its value is only ko or en — it is never used for advertising or analytics, and never linked across visits to identify who you are.
A second exception is a temporary key that groups one visit (2026-09-04).
To count which parts of a page you saw and how long you stayed per visit, the
events of that visit have to be recognisable as one visit. The key is a random value, it
disappears when you close the tab (sessionStorage), and it is not
connected to anything else we hold. Alongside it we send whether you have visited before as a
single true/false — the marker behind that (trops_seen) only
ever holds the value 1 and is never sent to our servers. So our
records alone cannot join two visits to the same person.
We count how often each page is opened and how often the main buttons are pressed (2026-08-18). From 4 September 2026 we also count which sections of a page you saw, how long you stayed on each, how far down you scrolled, and which next step you chose. For how you arrived we keep only one of five buckets (search, direct, referral, social, AI) and the domain of the site that sent you — the rest of that address is discarded.
None of this records cookies, device identifiers, IP addresses, or browser details. Because the temporary key lives only inside that visit and disappears when the tab closes, we cannot tell who you are. We know whether you have been here before only as true or false — not how many times.
What we receive and why
We receive nothing new. What follows is what we already received and have not yet deleted, and the table below is the whole of it.
| Where it came from | Items | Purpose | Retention |
|---|---|---|---|
| Document pre-check intake (up to 20 Aug 2026) |
Email The buyer documents you uploaded Your own form (optional) Counterparty country and HS code (optional) Two consents and when Payment details for paid intakes (order number, payment status) |
Running the comparison you asked for Delivering the summary Handling payment and refunds |
Deleted 30 days after intake. Deleted immediately if you ask. |
| Email enquiry | Whatever you wrote in your message | Answering your enquiry | Deleted once we have answered, or sooner if you ask. |
We never asked for national identification numbers or sensitive categories of data anywhere on this site. Documents you uploaded may contain such details; what remains is deleted on the schedule above regardless.
How long we keep it
Document pre-check intake — thirty days after intake we delete the files you uploaded and the intake record. This is also why the confirmation email carries a link rather than an attachment: a deletion policy cannot reach an attached file.
If you would rather not wait, write to contact@theo-ne.com. We confirm your request and delete them without delay. Once deleted, the same material cannot be sent to you again.
Email enquiry — your message exists only in our staff mailbox. We delete it once we have answered, or sooner if you ask.
Where Korean law requires records to be kept — contract, payment and consumer complaint records under the Act on Consumer Protection in Electronic Commerce, for example — we keep those for the period that law sets. Payment records are kept for five years, as set out in that Act's Enforcement Decree.
Personal information stored as an electronic file is deleted using a technical method that makes recovery or reconstruction impossible. Personal information recorded or stored on paper is destroyed by shredding or incineration.
Who processes it for us
Providers process data on our behalf, only as far as running the service requires, and none may use it for anything outside that.
| Processor | What they do |
|---|---|
| Resend | Sending notification and confirmation email |
| Supabase | Storing the intake records and uploaded files that remain · storing anonymous page-view and button-click counts |
| Vercel | Hosting the site and serving requests |
| Anthropic | OCR and AI analysis of uploaded documents |
Payments are taken in the Toss Payments window. Card numbers and other payment credentials go to the payment provider; we neither receive nor store them.
Some of these providers process personal information abroad, as set out below.
| Recipient | Items transferred | Country | Timing and method | Purpose | Retention |
|---|---|---|---|---|---|
| Supabase, Inc. (infrastructure: AWS) |
Email, company information, uploaded documents, payment-related identifiers | Republic of Korea (Seoul, ap-northeast-2) | Transmitted in real time as you use the service | Database storage, running the service | Until you close your account or the purpose is met |
| Supabase, Inc. (infrastructure: AWS) |
Pre-check intake details, email, uploaded documents | India (Mumbai, ap-south-1) | Transmitted in real time as you use the service | Running the pre-check service | Source files deleted or hashed 30 days later |
| Vercel Inc. | Access logs, general service usage data | United States | Transmitted in real time (hosting) | Website hosting | For the duration of the service |
| Anthropic, PBC | Content of uploaded documents subject to OCR and analysis | United States | Transmitted in real time when analysis is requested | AI-based document analysis | Automatically deleted within 30 days by default, never used for model training (whether a separate Zero Data Retention agreement applies is to be confirmed) |
| Toss Payments Corp. | Payment-related information | Republic of Korea | At the time payment is requested | Processing payments and settlement | 5 years (under the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce) |
The table above records where what remains is held today. Since trops.kr accepts no new intakes, no new cross-border transfer takes place. You have the right to refuse a cross-border transfer, and if you refuse you may ask us to delete what remains (§05).
What you can ask us to do
You may ask to see, correct or delete your personal information, or to stop us processing it. You may withdraw an optional consent at any time, and doing so does not affect the service you have already requested.
The link in your confirmation email shows the status of your intake. To have your files deleted, write to contact@theo-ne.com. We confirm your request and act on it without delay. Any other request reaches us at the same address.
Our privacy officer is Hana Beom, reachable at the email address above.
If matters are not resolved with us directly, you may also contact the following bodies.
- Personal Information Protection Commission — 02-2100-3025
- Personal Information Dispute Mediation Committee — 1833-6972 (kopico.go.kr, Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul)
- Personal Information Infringement Report Center, Korea Internet and Security Agency (KISA) — 118, no area code needed (privacy.kisa.or.kr)
This notice is governed by the laws of the Republic of Korea. If a dispute is brought to court, jurisdiction follows the Civil Procedure Act.
How we keep it safe
Storage keys are used on the server only and are never sent to the browser. Intake tables have row level security enabled, so nothing reads them outside the server path.
Confirmation emails carry a link, never an attachment — we avoid creating copies we cannot recall and cannot delete on schedule.
Material past its retention period is removed by a cleanup job.
When this notice changes
If the content changes we post the change and the date it takes effect on this page. Where a change is to your disadvantage we tell you before it takes effect.
Not settled yet
The following are for legal review to settle. We have left them blank rather than invent them.
- Whether a Zero Data Retention agreement applies to our data processing arrangement with Anthropic, PBC
If you need certainty on any of these, write to contact@theo-ne.com. Until the document is settled, what we actually do is exactly what is written above.